External risk intelligence

Open GenAI Stack Prompt Injection Code Execution Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-77177

The vulnerability exists in a GenAI stack used for backend services that process user input. Such stacks are commonly deployed as web applications or API endpoints to handle external requests, making them directly reachable from the internet in typical production environments.

Code Injection

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in the Open GenAI Stack, which is used in backend systems for products like WhatsApp. The issue allows for the execution of arbitrary code through a prompt injection flaw, potentially impacting systems that process user-generated content without proper sanitization. The main concern is confirming the relevance and exposure of this technology within our environment.

  • Unsanitized prompts can lead to code execution.
  • Affects AI backend systems processing user input.
  • Confirm relevance and exposure in our environment.

Attack Path

How an attacker could exploit the issue

An attacker can reach and trigger this vulnerability by sending specially crafted input to a vulnerable component. This input, when processed, allows the attacker to inject malicious code through prompt injection, potentially leading to unauthorized code execution on the server.

  • Entry condition: Unauthenticated network access.
  • Trigger point: Prompt injection via unsanitized input.
  • Resulting risk: Arbitrary code execution on the server.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability in the Open GenAI Stack, when used in backend services like those for Meta AI and WhatsApp, could allow an attacker to execute arbitrary code. This is possible through prompt injection, where specially crafted input using Jinja2 template syntax bypasses sanitization, leading to server-side expression evaluation.

  • Affected: Backend services processing user prompts.
  • Exposure: Code execution via unsanitized prompt injection.
  • Consequence: Potential unauthorized system access and control.

Operational Fix

Recommended remediation, mitigation, and detection steps

To address this critical vulnerability in the Open GenAI Stack used within Meta AI's backend for products like WhatsApp, the primary responsibility likely falls to the platform or infrastructure teams managing the AI backend services. The immediate first step is to conduct a thorough inventory to pinpoint all instances of the affected technology, determine their exposure and criticality, and identify the accountable service owner before planning any remediation.

  • Platform/Infrastructure teams should own the issue.
  • Verify affected technology deployment and reachability.
  • Plan remediation based on business risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Open GenAI Stack?

Open GenAI Stack (ogx-ai) is a software framework designed to help developers integrate generative AI capabilities into backend systems. It provides the underlying infrastructure to handle and process complex AI prompts. In practice, companies use it to power AI-driven features in messaging apps and other digital services, acting as the bridge between user input and the artificial intelligence models performing the work.

How does CVE-2026-77177 lead to code execution?

This vulnerability is classified as Improper Control of Generation of Code (CWE-94). The software fails to properly sanitize user-provided prompts before processing them. An attacker can supply input containing Jinja2 template syntax, which the system then interprets as executable code rather than plain text. This allows the server to unintentionally run arbitrary commands hidden within a prompt.

What conditions allow this prompt injection to succeed?

The flaw is triggered when an attacker sends specially crafted input to an application component that relies on the vulnerable Open GenAI Stack to interpret data. Critically, this does not occur if the input is treated strictly as static text or if the stack is configured to reject template syntax. The vulnerability exists specifically because the system evaluates expressions provided by users without a filtering or validation layer.

Why is this CVE relevant for my internet-facing systems?

According to Halo Surface Signal, this software is often deployed as a web application or API endpoint specifically to process external requests. Because it is designed to handle user-generated content, systems using this stack are frequently exposed to the internet. If an application is directly reachable from the web, it is highly likely to be a target for attackers seeking to exploit this code execution path.

Do I need to patch my infrastructure immediately?

Your first step is not immediate patching, but visibility. Because this is a backend framework, you must first conduct an inventory to locate where the Open GenAI Stack is running in your environment. Once identified, confirm if these instances are handling user input and assess their network accessibility. Work with your service owners to verify the deployment status and determine if the affected components are actively reachable by unauthorized users.

References